windows cannot backup one or more private keys because the csp does not support key export
hi,
i'm in process of changing our ca can issue sha256 certificates instead of "only" sha1 certificates.
however. step 1 ca, , step fails.
from within certificate authority mmc, try start backup:
but fails:
ok. maybe private key missing? how tell?
i have following ca certs:
if @ corresponding certs in certificate manager on ca (local computer/trusted root certification authorities), can find certs via thumbprint.
certificate #3 definitively have private key - i'm able export cert .pfx file.
any idea happened previous private keys? ca may unable create correct crls without previous private keys. if dont have access old keys anymore, can change the hkey_local_machine\system\currentcontrolset\services\certsvc\configuration\pdc-certificateauthority\cacerthash value remove old thumbprints , replace hypen this:
-
-
-
-
ba 01 61 3a 4c 6e 9e 84 bb 6b 72 19 89 77 47 48 4a 02 0d ba
stop , restart ca read value. recommend backing up/exporting registry key ca prior changes.
mark b. cooper, president , founder of pki solutions inc., former microsoft senior engineer , subject matter expert microsoft active directory certificate services (adcs). known “the pki guy” @ microsoft 10 years. co-founder of revocent (revocent.com) , certaccord product offers linux certificate enrollment microsoft ca. connect mark @ https://www.pkisolutions.com
Windows Server > Security
Comments
Post a Comment